Multichannel device utilizing a centralized out-of-band authentication system (COBAS)
Summary by NHIP
Centralized Out-of-Band Authentication System
The multichannel security system grants or denies host computer access by verifying login data and biometric samples through separate communication channels. A security computer matches re-entered predetermined data against stored records and instructs the host to allow entry only after confirming the match via an auditory prompt on a telephone keypad.
Claim Score by NHIP
Abstract
A multichannel security system is disclosed, which system is for granting and denying access to a host computer in response to a demand from an access-seeking individual and computer. The access-seeker has a peripheral device operative within an authentication channel to communicate with the security system. The access-seeker initially presents identification and password data over an access channel which is intercepted and transmitted to the security computer. The security computer then communicates with the access-seeker. A biometric analyzer—a voice or fingerprint recognition device—operates upon instructions from the authentication program to analyze the monitored parameter of the individual. In the security computer, a comparator matches the biometric sample with stored data, and, upon obtaining a match, provides authentication. The security computer instructs the host computer to grant access and communicates the same to the access-seeker, whereupon access is initiated over the access channel.

Term
Term ended
Expired 2 October 2022, 4 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
34 claims: 5 independent, 29 dependent
- 1A multichannel security system for accessing a host computer comprising:an access channel comprising: interception means for receiving and verifying a login identification originating from a demand from an accessor for access to said host computer;and an authentication channel comprising: a security computer for receiving from said interception means said demand for access together with said login identification and for communicating access information to said host computer and for communicating with a peripheral device of said accessor;a database having at least one peripheral address record corresponding to said login identification;prompt means for instructing said accessor to re-enter predetermined data at and retransmit predetermined data from said peripheral device;and comparator means for authenticating access demands in response to the retransmission of said predetermined data by verifying a match between said predetermined data and said re-entered and retransmitted data, wherein said security computer outputs an instruction to the host computer to either grant access thereto using said access channel or to deny access thereto.
- 11A multichannel security system for granting and denying access to a host computer, said access in response to a demand from an accessor for access to the host computer, said accessor having a cellular telephone for providing communications to the security system, said multichannel security system comprising:a login identification accompanying said demand from said accessor;interception means for receiving and verifying said login identification, said interception means in an access channel;an authentication channel operating independently from said access channel, said authentication channel comprising: a security computer adapted in an access-channel mode to receive from said interception means said demand for access together with said login identification and to communicate access information to said host computer and in an authentication-channel mode communications with said cellular telephone;a subscriber database for retrieval of peripheral addresses corresponding to said login identification;wherein said security computer is adapted to connect to said associated cellular telephone of said accessor;prompt means for instructing said accessor to re-enter predetermined data at and retransmit predetermined data from said cellular telephone;comparator means for authenticating access demands in response to retransmission of predetermined data from said cellular telephone;said security computer, upon verifying a match between said predetermined data and said re-entered and retransmitted data, providing in the access-channel mode instructions to the host computer to grant access thereto along said access channel;authentication program means, operating independently from said host computer, for authenticating said accessor demanding access to said host computer;a biometric analyzer operating in response to said instructions from said authentication program means to analyze a monitored parameter of said accessor;and, a biometric parameter database addressable by said biometric analyzer for retrieval of a previously registered sample of said accessor, said sample corresponding to the identification of said accessor.
- 18A multichannel security system for granting and denying access to a host computer, said access in response to a demand over the Internet from an accessor for access to the host computer, said accessor having a personal digital assistant (PDA) for providing communications to the security system, said multichannel security system comprising:a login identification accompanying said demand over the internet from said accessor;interception means for receiving and verifying said login identification, said interception means in an access channel;an authentication channel operating independently from said access channel and, said authentication channel, in turn, comprising;a security computer adapted in an access-channel mode to receive from said interception means said demand together with said login identification and to communicate access information to said host computer and in an authentication-channel mode communications with said PDA;a subscriber database for retrieval of peripheral addresses corresponding to said login identification;said security computer adapted to connect to said PDA;prompt means for instructing said accessor to re-enter predetermined data at and retransmit predetermined data from said PDA;comparator means for authenticating access demands in response to retransmission of predetermined data from said PDA;said security computer, upon verifying a match between said predetermined data and the re-entered and retransmitted data, providing in the access-channel mode instructions to the host computer to grant access thereto along said access channel;authentication program means, operating independently from said host computer, for authenticating an accessor demanding access to said host computer;a biometric analyzer operating in response to instructions from said authentication program means to analyze a monitored parameter of said accessor;and, a biometric parameter database addressable by said biometric analyzer for retrieval of a previously registered sample of said accessor, said sample corresponding to the identification of said accessor.
- 21Broadest claimClaim Score 54, average(NHIP)A method for accessing a host computer comprising the steps of:in an access channel, receiving at a control module a login identification from an accessor;in an authentication channel that is separate from the access channel: providing a security computer comprising a subscriber database, the database having at least one peripheral address of a peripheral device;receiving in the security computer an intercepted login identification corresponding to the login identification;retrieving a peripheral address corresponding to the intercepted login identification;outputting to the peripheral address a first instruction to re-enter predetermined data at and retransmit the predetermined data from the peripheral device;comparing at the security computer the re-entered and retransmitted data;and outputting a second instruction to the host computer to either grant access thereto using the access channel or to deny access thereto.
- 32An out-of-band computer security system comprising:a security computer in an authentication channel for communicating with a telephonic device and for receiving an intercepted demand for access to a host computer together with a login identification from an accessor in an access channel that is separate from the authentication channel;a subscriber database addressable by the security computer having at least one telephone number corresponding to the intercepted login identification;a device operable in response to a first instruction from the security computer to call the at least one telephone number and connect the telephonic device to the security computer;prompt means for outputting a second instruction at the telephonic device to re-enter predetermined data at and retransmit predetermined data from the telephonic device;and comparator means in said security computer for authenticating the access demand in response to the retransmission of the predetermined data from the telephonic device;wherein the security computer, upon verifying a match between the predetermined data and the re-entered and retransmitted data, authenticates the accessor and instructs the host computer to grant access thereto in the access channel.
Independent claims5
83 paragraphs in 6 sections, as filed
RELATED APPLICATION
This is a continuation-in-part of an application entitled OUT-OF-BAND SECURITY NETWORKS FOR COMPUTER NETWORK APPLICATIONS, Ser. No. 09/655,297, filed Sep. 5, 2000 and now abandoned. This application is incorporated herein by reference.
BACKGROUND OF THE INVENTION
1. Field of the Invention
This invention relates to security networks for computer network applications, and, more particularly, to a security network which provides user authentication by an out-of-band system that is entirely outside the host computer network being accessed. In addition, the out-of-band system optionally includes provision for biometric identification as part of the authentication process.
2. Background of the Invention
In the past, there have typically been three categories of computer security systems, namely, access control, encryption and message authentication, and intrusion detection. The access control systems act as the first line of defense against unwanted intrusions, and serve to prevent hackers who do not have the requisite information, e.g. the password, etc., from accessing the computer networks and systems. Secondly, the encryption and message authentication systems ensure that any information that is stored or in transit is not readable and cannot be modified. In the event that a hacker is able to break into the computer network, these systems prevent the information from being understood, and, as such, encryption systems as the second line of defense. Further intrusion detection systems uncover patterns of hacker attacks and viruses and, when discovered provide an alarm to the system administrator so that appropriate action can be taken. Since detection systems operate only after a hacker has successfully penetrated a system, such systems act as a third line of defense.
Obviously, as an access control system is the first line of defense, it is important that the selection thereof be well-suited to the application. In access control systems there is a broad dichotomy between user authentication and host authentication systems. In current practice, the most common user authentication systems include simple password systems, random password systems, and biometric systems. The simple password systems are ubiquitous in our society with every credit card transaction using a pin identification number, every automatic teller machine inquiry looking toward a password for access, and even telephone answering messages using simple password systems for control.
Additionally, when random password systems are used, another level of sophistication is added. In these systems, the password changes randomly every time a system is access. These systems are based on encryption or a password that changes randomly in a manner that is synchronized with an authorization server. The Secure ID card is an example of such a system. Random password systems require complimentary software and/or hardware at each computer authorized to use the network.
In biometric systems, characteristics of the human body, such as voice, fingerprints or retinal scan, are used to control access. These systems require software and/or hardware at each computer to provide authorization for the use of the network.
Another category of access control is that of host authentication. Here the commonest systems are those of “callback” and “firewall” systems. Callback systems are those systems which work by calling a computer back at a predetermined telephone number. These systems authenticate the location of a computer and are suitable for dial-up (modem) networks; however, such systems are ineffective when the attack comes via the Internet. On the other hand, firewall systems are designed to prevent attacks coming from the Internet and work by allowing access only from computers within a network. Even though firewall systems are implemented either as standalone systems or incorporated into routers, skilled hackers are able to penetrate host authentication systems.
Typically, access-control security products, as described above, are in-band authentication systems with the data and the authentication information on the same network. Thus, upon accessing a computer, a computer prompt requests that you enter your password and, upon clearance, access is granted. In this example, all information exchanged is on the same network or in-band. The technical problem created thereby is that the hacker is in a self-authenticating environment.
Except for callback systems, the above access control products authenticate only the user and not the location. When computer networks could only be accessed by modems, the authentication of location by dialing back the access-requesting computer, provided a modicum of security. Now, as virtually all computer networks are accessible by modem-independent internet connection, location authentication by callback is no longer secure. The lack of security arises as there is no necessary connection between the internet address and a location, and, in fact, an internet address most often changes from connection to connection. Thus, callback systems are rendered useless against attacks originating from the internet.
In preparing for this application, a review of various patent resources was conducted. The review resulted in the inventor gaining familiarity with the following patents:
<tables id="TABLE-US-00001" num="00001"><table frame="none" colsep="0" rowsep="0"><tgroup align="left" colsep="0" rowsep="0" cols="5"><colspec colname="1" colwidth="35pt" align="center" /><colspec colname="2" colwidth="35pt" align="center" /><colspec colname="3" colwidth="56pt" align="left" /><colspec colname="4" colwidth="42pt" align="left" /><colspec colname="5" colwidth="49pt" align="left" /><thead><row><entry namest="1" nameend="5" align="center" rowsep="1" /></row><row><entry>Item No.</entry><entry>Pat. No.</entry><entry>Inventor</entry><entry>Orig. Class</entry><entry>Date</entry></row><row><entry namest="1" nameend="5" align="center" rowsep="1" /></row></thead><tbody valign="top"><row><entry /></row></tbody></tgroup><tgroup align="left" colsep="0" rowsep="0" cols="5"><colspec colname="1" colwidth="35pt" align="char" char="." /><colspec colname="2" colwidth="35pt" align="center" /><colspec colname="3" colwidth="56pt" align="left" /><colspec colname="4" colwidth="42pt" align="left" /><colspec colname="5" colwidth="49pt" align="left" /><tbody valign="top"><row><entry>1</entry><entry>6,408,062</entry><entry>Cave, Ellis K.</entry><entry>379/210.01</entry><entry>June 2002</entry></row><row><entry>2</entry><entry>5,901,284</entry><entry>Hamdy-Swink,</entry><entry>713/200</entry><entry>May 1999</entry></row><row><entry /><entry /><entry>Katheryn A.</entry></row><row><entry>3</entry><entry>5,898,830</entry><entry>Wesinger, Jr.,</entry><entry>395/187.01</entry><entry>April 1999</entry></row><row><entry /><entry /><entry>et al.</entry></row><row><entry>4</entry><entry>5,872,834</entry><entry>Teitelbaum</entry><entry>379/93.03</entry><entry>February 1999</entry></row><row><entry>5</entry><entry>5,826,014</entry><entry>Coley, et al.</entry><entry>718,201</entry><entry>October 1998</entry></row><row><entry>6</entry><entry>5,787,187</entry><entry>Bouchard</entry><entry>382/115</entry><entry>July 1998</entry></row><row><entry>7</entry><entry>5,680,458</entry><entry>Spelman, et al.</entry><entry>380/21</entry><entry>October 1997</entry></row><row><entry>8</entry><entry>5,621,809</entry><entry>Bellegarda, et al.</entry><entry>382/116</entry><entry>April 1997</entry></row><row><entry>9</entry><entry>5,615,277</entry><entry>Hoffman</entry><entry>382/115</entry><entry>March 1997</entry></row><row><entry>10</entry><entry>5,588,060</entry><entry>Aziz</entry><entry>380/30</entry><entry>December 1996</entry></row><row><entry>11</entry><entry>5,548,646</entry><entry>Aziz, et al.</entry><entry>380/23</entry><entry>August 1996</entry></row><row><entry>12</entry><entry>5,153,918</entry><entry>Tuai, Gregory</entry><entry>713/182</entry><entry>October 1992</entry></row><row><entry namest="1" nameend="5" align="center" rowsep="1" /></row></tbody></tgroup></table></tables>
In general terms, the patents all show a portion of the authentication protocol and the data transferred in the same channel or “in-band”. For purposes of this discussion “in-band” operation is defined as one conducted wholly within a single channel or loop. Likewise, an “out-of-band” operation is defined as one using an authentication channel that is separated from the channel carrying the information and therefore is nonintrusive as it is carried over separate facilities, frequency channels, or time slots than those used for actual information transfer.
The patent to E. K. Cave, U.S. Pat. No. 6,408,062, Item 1 above, describes a callback system. Here, the user is prequalified so that he does not get charged for calls that are not completed to the called party. However, here the authentication and the administrative function are in the same loop.
In Item 3, the patent to Wesinger et al., U.S. Pat. No. 5,898,830 ('830) is a firewall patent. Here, the inventor attempts to enhance security by using out-of-band authentication. In his approach, a communication channel, or medium, other than the one over which the network communication takes place, is used to transmit or convey an access key. The key is transmitted from a remote location (e.g., using a pager or other transmission device) and, using a hardware token, the key is conveyed to the local device. In the Wesinger '830 system, to gain access, a hacker must have access to a device (e.g., a pager, a token, etc.) Used to receive the out-of-band information. Pager beep-back or similar authentication techniques may be especially advantageous in that, if a hacker attempts unauthorized access to a machine while the authorized user is in possession of the device, the user will be alerted by the device unexpectedly receiving the access key. The key is unique to each transmission, such that even if a hacker is able to obtain it, it cannot be used at other times or places or with respect to any other connection.
Next, turning to Item 7, the patent to Spelman et al., U.S. Pat. No. 5,680,458 ('458), a method of recovering from the compromise of a root key is shown. Here, following the disruption of a new replacement key, an out-of-band channel is used by a central authority to publish a verification code which can be used by customers to verify the authenticity of the emergency message. The Spelman '458 patent further indicates that the central authority uses the root key to generate a digital signature which is appended to the emergency message to verify that the emergency message is legitimate.
Hoffman, U.S. Pat. No. 5,615,277, Item 9, is next discussed. Here, biometrics are combined with a tokenless security and the patent describes a method for preventing unauthorized access to one or more secured computer systems. The security system and method are principally based on a comparison of a unique biometric sample, such as a voice recording, which is gathered directly from the person of an unknown user with an authenticated unique biometric sample of the same type. The Hoffman technology is networked to act as a full or partial intermediary between a secured computer system and its authorized users. The security system and method further contemplate the use of personal codes to confirm identifications determined from biometric comparisons, and the use of one or more variants in the personal identification code for alerting authorities in the event of coerced access.
Items 10 and 11 have a common assignee, Sun Microsystems, Inc., and both concern encryption/decryption keys and key management.
The patent to Tuai, U.S. Pat. No. 5,153,918 ('918) describes an in-band authentication system which uses a callback system after authentication. Within the authentication system, Tuai '918 employs a voice verification technique.
The submission of the above list of documents is not intended as an admission that any such document constitutes prior art against the claims of the present application. Applicant does not waive any right to take any action that would be appropriate to antedate or otherwise remove any listed document as a competent reference against the claims of the present application. None of the above show the novel and unobvious features of the invention described hereinbelow.
SUMMARY
In general terms, the invention disclosed hereby includes in the embodiments thereof, a unique combination of user and host authentication. The security system of the present invention is out-of-band with respect to the host computer and is configured to intercept requests for access. The first step in controlling the incoming access flow is a user authentication provided in response to prompts for a user identification and password. After verification at the security system, the system operating in an out-of-band mode, uses telephone dialup for location authentication and user authentication via a password entered using a telephone keypad. In addition and optionally the system provides further authentication using a biometric system. When voice recognition is employed for the biometric component, the user speaks a given phrase which the system authenticates before permitting access. Upon granting of access, the user now for the first time enters the in-band operating field of the host computer.
OBJECT AND FEATURES OF THE INVENTION
It is an object of the present invention to provide a host computer with a cost effective, out-of-band security network that combines high security and tokenless operation.
It is a further object of the present invention to provide a network to isolate the authentication protocol of a computer system from the access channel therefor.
It is yet another object of the present invention to provide a separate security network which acts conjunctively with or as an overlying sentry box to the existing security system provided by the host computer.
It is still yet another object of the present invention to provide an authentication using a biometric component, such as speech recognition, to limit access to specific individuals.
It is a feature of the present invention that the security network achieves high security without encryption and decryption.
It is another feature of the present invention to have a callback step that restricts authentication to a given instrument thereby enabling restriction to a fixed location.
It is yet another feature of the present invention to combine callback and speech recognition in an out-of-band security facility.
Other objects and features of the invention will become apparent upon review of the drawings and the detailed description which follow.
BRIEF DESCRIPTION OF THE DRAWINGS
In the following drawings, the same parts in the various views are afforded the same reference designators.
<figref idref="DRAWINGS">FIG. 1</figref> is a schematic diagram of the prior art security system;
<figref idref="DRAWINGS">FIG. 1A</figref> is a schematic diagram of the security system of the present invention as applied to the internet in which an external accessor in a wide area network seeks entry into a host system;
<figref idref="DRAWINGS">FIG. 2</figref> is a schematic diagram of the apparatus required for the security system shown in <figref idref="DRAWINGS">FIG. 1</figref>;
<figref idref="DRAWINGS">FIG. 3</figref> is a schematic diagram of the software program required for the security system shown in <figref idref="DRAWINGS">FIG. 1</figref> in which various program modules are shown for corresponding functions of the system and each module is shown in relation to the control module thereof;
<figref idref="DRAWINGS">FIG. 4</figref> is a detailed schematic diagram of the software program required for the line module of the security system shown in <figref idref="DRAWINGS">FIG. 3</figref>;
<figref idref="DRAWINGS">FIG. 5</figref> is a detailed schematic diagram of the software program required for the speech module of the security system shown in <figref idref="DRAWINGS">FIG. 3</figref>;
<figref idref="DRAWINGS">FIG. 6</figref> is a detailed schematic diagram of the software program required for the administration module of the security system shown in <figref idref="DRAWINGS">FIG. 3</figref>;
<figref idref="DRAWINGS">FIG. 7</figref> is a detailed schematic diagram of the software program required for the client/server module of the security system shown in <figref idref="DRAWINGS">FIG. 3</figref>;
<figref idref="DRAWINGS">FIG. 8</figref> is a detailed schematic diagram of the software program required for the database module of the security system shown in <figref idref="DRAWINGS">FIG. 3</figref>;
<figref idref="DRAWINGS">FIG. 9A through 9E</figref> is a flow diagram of the software program required for the security system shown in <figref idref="DRAWINGS">FIG. 1</figref>;
<figref idref="DRAWINGS">FIG. 10</figref> is a schematic diagram of a second embodiment of the security system of the present invention as applied to the intranet in which an internal accessor in a local area network seeks entry into a restricted portion of the host system;
<figref idref="DRAWINGS">FIG. 11</figref> is a schematic diagram of the third embodiment of the security system using as peripheral devices a cellular telephone and a fingerprint verification device;
<figref idref="DRAWINGS">FIG. 12</figref> is a detailed schematic diagram of the software program required for the fingerprint module of the security system shown in <figref idref="DRAWINGS">FIG. 11</figref>; and,
<figref idref="DRAWINGS">FIG. 13</figref> is a detailed schematic diagram of the fourth embodiment of the security system using as peripheral devices a personal digital assistant (PDA) and the associated fingerprint verification device.
DESCRIPTION OF THE PREFERRED EMBODIMENT
In the description that follows, the prior art is shown in <figref idref="DRAWINGS">FIG. 1</figref>. In a typical call-back system which this epitomizes, the user from his computer <b>10</b> accesses through an optional voice encoder <b>12</b> and, along a single authentication channel. The channel includes an in-band arrangement of the user's modem <b>14</b>, the host computer modem <b>16</b> and the authentication controller <b>17</b>. In a specific example of this, in the Tuai '918 system, see supra, which uses voice verification, the user accesses a host computer <b>18</b> via modems <b>14</b> and <b>16</b>. The access attempt is intercepted by the controller <b>17</b> which prompts the user to enter a USER ID and speak a phrase for voice verification. If the verification is successful, the controller <b>17</b> acting within the single communication channel connects the user computer to the host computer. Both the USER ID and the voice password are sent along the same pathway and any improper accessor into this channel has the opportunity to monitor and/or enter both identifiers.
The out-of-band security system networks for computer network applications is described in two embodiments. The first describes an application to a wide area network, such as the internet, wherein the person desiring access and the equipment used thereby are remote from the host computer. In this description and consistent with Newton's <i>Telecom Dictionary </i>(19<sup>th </sup>Ed.), an “out-of-band” system is defined herein as one having an authentication channel that is separated from the information channel and therefore is nonintrusive as it is carried over separate facilities than those used for actual information transfer. The second embodiment describes the application of the disclosed invention to a local area network wherein the person desiring access and the equipment used thereby are within the same network (referred to as the “corporate network”) as the host computer. For purposes of this description the person desiring access and the equipment used thereby are referred collectively as the “accessor”.
In <figref idref="DRAWINGS">FIG. 1</figref>, a general overview of the first embodiment of the out-of-band security networks for computer network applications of this invention is shown and is referred to generally by the reference designator <b>20</b>. Here the accessor is the computer equipment <b>22</b>, including the central processing unit and the operating system thereof, and the person or user <b>24</b> whose voice is transmittable by the telephone <b>26</b> over telephone lines <b>28</b>. The access network <b>30</b> is constructed in such a manner that, when user <b>24</b> requests access to a web page <b>32</b> located at a host computer or web server <b>34</b> through computer <b>22</b>, the request-for-access is diverted by a router <b>36</b> internal to the corporate network <b>38</b> to an out-of-band security network <b>40</b>. Authentication occurs in the out-of-band security network <b>40</b>, which is described in detail below.
This is in contradistinction to present authentication processes as the out-of-band security network <b>40</b> is isolated from the corporate network <b>38</b> and does not depend thereon for validating data. The first shows a biometric validation which, in this case, is in the form of voice recognition and is within voice network <b>42</b>. While voice recognition is used herein, it is merely exemplary of many forms of recognizing or identifying an individual person. Others include, but are not limited to fingerprint identification, iris recognition, retina identification, palms recognition, and face recognition. Each of these are similar to the first embodiment in that these are a requirement for monitoring the particular parameter of the individual person; including the parameter to a mathematical representation or algorithm therefore; retrieving a previously stored sample (biometric data), thereof from a database and comparing the stored sample with the input of the accessor.
Referring now to <figref idref="DRAWINGS">FIG. 2</figref> a block diagram is shown for the hardware required by the out-of-band security network for computer network applications of this invention. The request-for-access is forwarded from the router <b>36</b> of the corporate network to a data network interface <b>50</b> which, in turn, is constructed to transfer the request to a dedicated, security network computer <b>52</b> over a data bus <b>48</b>. The computer <b>52</b> is adapted to include software programs, see infra, for receiving the user identification and for validating the corresponding password, and is further adapted to obtain the user telephone number from lookup tables within database <b>54</b> through data bus <b>48</b>. The computer <b>52</b> is equipped to telephone the user through a PBX interface <b>56</b> and voice bus <b>58</b>. For voice recognition, a speech or biometric system <b>60</b> is provided to process requested speech phrases repeated by the user <b>24</b> which is verified within the security computer <b>52</b>. Upon authentication, access is granted through the data network interface <b>50</b>.
Referring now to <figref idref="DRAWINGS">FIGS. 3 through 8</figref> the software architecture supporting the above functions is next described. The security computer <b>52</b>, <figref idref="DRAWINGS">FIG. 2</figref>, is structured to include various functional software modules, <figref idref="DRAWINGS">FIG. 3</figref>, namely, a control module <b>62</b>, a line module <b>64</b>, a speech module including a biometric for voice recognition <b>66</b>, an administration module <b>68</b>, a client/server module <b>70</b>, and a database module <b>72</b>. The software program of the control module <b>62</b> functions and interconnects with the other modules (line, speech, administration, client/server and database modules) to control the processing flow and the interfacing with the internal and external system components.
As will be understood from the flow diagram description, infra, the control module <b>62</b> software of the security computer <b>52</b> incorporates a finite state machine, a call state model, process monitors, and fail-over mechanisms. The software program of the line module <b>64</b> is structured to provide an interface with the telephone network. The software program of the speech module <b>66</b> is structured to perform processing functions such as, but not limited to, speech verification, text-to-speech conversion and announcements. The software program of the administration module <b>68</b> is structured to archive the records of each call made, to provide security and management functions, and to process any alarms generated. The software program of the client/server module <b>70</b> is structured to enable a host computer or a web server <b>34</b> to interface with the out-of-band security network <b>40</b>. The software program of the database module <b>72</b> is comprised of the databases to support the security network <b>40</b> which in the present invention includes an audit database, a subscriber database, a speech database, an announcement database, and a system database.
Referring now to <figref idref="DRAWINGS">FIG. 4</figref>, the line module <b>64</b> is described in further detail. The analog telephone interface <b>74</b> is the equipment, such as voice bus <b>58</b> and PBX interface <b>56</b>, that interfaces to an analog line. The analog telephone interface <b>74</b> is, in turn, controlled by software program of the analog line driver <b>76</b>. Similarly, digital telephone interface <b>78</b> is the equipment, such as data bus <b>48</b> and PBX interface <b>56</b>, that interfaces to a digital line (T1 or ISDN PRI)a. The digital telephone interface <b>78</b> is, in turn, controlled by the software program of the digital line driver <b>80</b>. The software progarm of the telephone functions module <b>82</b> is structured to accommodate functions such as, Call Origination, Call Answer, Supervisory signaling, Call Progress signaling, Ring generation/detection, DTMF generation/detection, and line configuration.
In <figref idref="DRAWINGS">FIG. 5</figref> the speech module <b>66</b> architecture is detailed. The speech verification (SV) hardware <b>84</b>, (part of speech system <b>60</b>, <figref idref="DRAWINGS">FIG. 2</figref>) consists of digital signal processors that utilize SV algorithms for verification of an accessor's spoken password. The speech verification hardware <b>84</b> is controlled by the software program of the SV hardware driver <b>86</b>. The software program of the speech verification processing unit <b>88</b> provides an interface with control module <b>62</b> and is structured to respond to queries therefrom for verifying an accessor's spoken password. Also, the SV processing unit <b>88</b> enables the enrollment of users with the speech password and the interaction of the speech database of database module <b>72</b>.
The text-to-speech (TTS) hardware <b>90</b> consists of digital signal processors that utilize TTS algorithms. The text-to-speech hardware <b>90</b> is controlled by the software program of the TTS hardware driver <b>92</b>. The software program of the TTS processing unit <b>94</b> provides an interface with the control module <b>62</b> and, as required by the control module <b>62</b>, converts text strings to synthesized speech. The announcement hardware <b>96</b> consists of digital signal processors that utilize speech algorithms to record and play announcements. The announcement hardware is controlled by the software program of the announcement hardware driver <b>98</b>. The software program of the announcement processing unit <b>100</b> also provides an interface with control module <b>62</b>; upon demands of the control module <b>62</b>, supplies stored announcements; and interacts with the announcements database of database module <b>72</b>.
In <figref idref="DRAWINGS">FIG. 6</figref>, the software program of the administration module <b>68</b> is presented in more detail. As the administration module <b>68</b> interfaces with the control module <b>62</b>, see supra, a subprogram, namely, a control module interface <b>102</b> is constructed to manage the communication therebetween. The administration module <b>68</b> further includes software to provide an audit trail of all calls requesting access. This unit or audit log <b>104</b> creates records about each call, which records are stored in the audit database of the database module <b>72</b>. Any alarms caused as a result of errors, threshold crossing or system failures are processed by the software program of alarm module <b>106</b>. For remote administration of the out-of-band security system <b>40</b> of this invention, the software program of the network interface <b>108</b> is provided, which software communicates with the corporate network <b>38</b> (via network adapters). Access to the out-of-band security system <b>40</b> for administrative purposes is controlled by security module <b>110</b>. Similar to the network interface <b>108</b>, the software program of the management module <b>112</b> provides for the remote management of the out-of-band security system <b>40</b> for configuration, status reporting, software upgrades and trouble-shooting purposes.
Referring now to <figref idref="DRAWINGS">FIG. 7</figref>, the software program of the client/server module <b>70</b> that secures the host computer or web server or router <b>34</b> of the corporate network <b>38</b> through the out-of-band security system <b>40</b> of this invention is shown in detail. Here, the client protocol module <b>114</b> provides the interfacing means for the host computer or web server <b>34</b> and communicates with the out-of-band security system <b>40</b> using a proprietary protocol. Alternatively, standard protocols such as RADIUS and TACACS can be used. The server protocol module <b>116</b> interfaces with the control module <b>62</b> and manages the interaction with the client protocol module <b>114</b>.
In <figref idref="DRAWINGS">FIG. 8</figref> a detailed schematic diagram is shown of the software program required for the database module <b>72</b> of the out-of-band security system <b>40</b> of this invention. The database module <b>72</b> is the recordkeeping center, the lookup table repository, and the archival storehouse of the system. In the above description numerous relationships to this module have already been drawn. The database module <b>72</b> communicates through control module interface <b>118</b> to the control module <b>62</b>.
Two types of communications are channeled to and from the database module <b>72</b>, namely, communicating data for use during operations through database access interface <b>120</b> and communicating data for maintenance and provisioning of the out-of-band security system through database provisioning interface <b>122</b>. While the databases described herein are specifically related to the application of this embodiment to voice recognition the formation of specific databases, e.g. a different set of samples of biometric parameters or characteristics, is within the contemplation of the invention. The databases hereof are the audit database <b>124</b> for the call records; the subscriber database <b>126</b> for subscriber information; the speech database <b>128</b> for aid in verifying an accessor's spoken password; the announcements database <b>130</b> for announcements to be played to users during a call; and, system database <b>132</b> for system related information (e.g. configuration parameters).
In <figref idref="DRAWINGS">FIGS. 9A through 9E</figref> the flow diagram for the above software program operation is shown and is described hereinbelow. Thus, while the preceding in discussing the network architecture for the out-of-band security system <b>40</b> explains the access portion of the program—the operations side—and the configuration and maintenance portion of the program—the provisioning side, the description which follows is of the software operation of the out-of-band security system <b>40</b> from the receipt of a request-to-access inquiry to a granting-of-access or denial-of-access result. The logic description that follows reflects the accessor's inputs and the programmed processes along the logical pathway from the receipt of a request-to-access inquiry to a granting-of-access or denial-of-access result.
The pathway commences at the REQUEST FOR ACCESS block <b>150</b> whereby a request to enter the host computer or web server <b>34</b> is received from the user at the remote computer <b>22</b>. The user requesting access to the host computer from the remote computer is immediately prompted to login at the LOGIN SCREEN PRESENTED block <b>152</b>. While the login procedure here comprises the entry of the user identification and password and is requested by the host computer <b>34</b>, such information request is optionally a function of the security computer <b>40</b>. Upon entry of data by user at the ENTRY OF ID AND PASSWORD block <b>154</b> the information is passes to the security computer <b>40</b>.
As described in the software architecture review, supra, the software pathway of the login data is first to client module <b>114</b> at SEND LOGIN DATA TO CLIENT MODULE block <b>156</b> and then successively to server module <b>116</b> at SEND LOGIN DATA TO SERVER MODULE block <b>158</b> and to control module <b>62</b> at SEND LOGIN DATA TO CONTROL MODULE block <b>160</b>. In transmitting the login data from the client module <b>114</b> to the server module a proprietary protocol is employed, which protocol includes encryption of the data using standard techniques. The verification process is continued at the control module <b>62</b> which next enters the subscriber database <b>126</b> and retrieves at CONTROL MODULE QUERIES SUBSCRIBER DATABASE AND RETRIEVES PASSWORD ASSOCIATED WITH LOGIN ID block <b>162</b> the password associated with the logged in identification. The control module <b>62</b> verifies at CONTROL MODULE VERIFIES PASSWORD block <b>164</b> that the password received from the remote computer <b>22</b> is the same as the password retrieved from the subscriber database <b>126</b>.
Upon verification, the control module <b>62</b> at DOES THE PASSWORD MATCH? block <b>166</b> sends confirmation thereof back along the software pathway to inform the user of the event. Upon failure to verify, the control module <b>62</b> at DOES THE PASSWORD MATCH? block <b>166</b> initiates an alarm indicating that the login conditions were not met. The software program upon an alarm condition terminates processing. Alternatively, the program offers the user an opportunity to retry whereupon there is a retracement through the same software path as just described and then, upon repeated alarm occurrence, the software terminates processing. The retry process may be limited to a specified number of times. The message that the verification has been achieved is transmitted along the software pathway substantially in the reverse manner as the login data transmission.
From the control module <b>62</b>, the verification is first received by the server module <b>116</b> and at SEND VERIFICATION FROM SERVER MODULE TO CLIENT MODULE block <b>168</b> the verification message along with the information that the authentication is proceeding is transmitted to the client module <b>114</b>. In transmitting these messages to the client module <b>114</b> from the server module a proprietary protocol is employed, which protocol includes decryption of the data, where required, using standard techniques. The client module <b>114</b> transmits at SEND VERIFICATION FROM CLIENT MODULE TO HOST COMPUTER block <b>170</b> the message to the host computer <b>34</b>. Finally, the host computer <b>34</b> transmits at SEND VERIFICATION FROM HOST COMPUTER TO REMOTE COMPUTER block <b>172</b> the message that the login verification is complete is sent to the remote computer <b>22</b> and prompts the person or user <b>24</b> to stand by for a telephonic callback.
Now with the control module <b>62</b> having verified the remote computer <b>22</b>, the software program hereof is constructed to have the control module <b>62</b> at CALLBACK INITIATED BY CONTROL MODULE block <b>174</b> initiate out-of-band the call-back procedure to the user <b>24</b>. The control module <b>62</b> queries the subscriber database <b>126</b> and retrieves therefrom the telephone number associated with the login identification. Based on the data retrieved from the subscriber database, the control module <b>62</b> instructs the line module <b>64</b> at DIAL USER TELEPHONE NUMBER block <b>176</b> to call user <b>24</b>. Upon user <b>24</b> answering the telephone at USER ANSWERS TELEPHONE block <b>178</b>, the software pathway continues with the line module <b>64</b> relaying to the control module <b>62</b> at CONTROL MODULE NOTIFIED BY LINE MODULE OF OFF-HOOK CONDITION block <b>180</b> that the user's telephone is off-hook. The program is constructed so that the control module <b>62</b> then instructs the speech module <b>66</b> at SPEECH MODULE INSTRUCTED BY CONTROL MODULE TO RETRIEVE PASSWORD block <b>182</b> to retrieve (or generate) a DTMF password. To accomplish this, the speech module <b>66</b> now queries the announcement database <b>130</b> at PROMPT RETRIEVED BY SPEECH MODULE block <b>184</b> retrieves the prompt to be played to the user <b>24</b>. Alternatively, the password for the prompt is generated and synthesized by the text-to-speech system <b>90</b>, <b>92</b> and <b>94</b> of the speech module <b>66</b>.
At PROMPT PLAYED BY SPEECH MODULE TO USER block <b>186</b>, the user <b>24</b> is instructed to impress the DTMF password on the telephone keypad. The program progresses so that after the user <b>24</b> enters the DTMF password on the telephone keypad at USER ENTER DTMF PASSWORD block <b>188</b>, the line module <b>64</b> at LINE MODULE TRANSMITS ENTRY TO CONTROL MODULE block <b>190</b> notifies the control module <b>62</b> of the entry made by user <b>24</b>. In the manner similar to the login password, supra, the control module <b>62</b> queries the subscriber database and, at CONTROL MODULE RETRIEVES DTMF PASSWORD block <b>192</b>, retrieves the password or the generated password associated with the subscriber. At CONTROL MODULE VERIFIES DTMF PASSWORD block <b>194</b>, the control module <b>62</b> verifies that the password entered at the telephone keypad by the user matches the password retrieved from the subscriber database. Upon verification, the control module <b>62</b> at DOES THE DTMF PASSWORD MATCH? block <b>196</b> sends confirmation thereof back along the software pathway to inform the user of the event.
Upon failure to verify, the control module <b>62</b> at DOES THE DTMF PASSWORD MATCH? block <b>196</b> initiates an alarm indicating that the login conditions were not met. The software program upon an alarm condition terminates processing. As in the previous password verification and alternatively, the program offers the user an opportunity to retry. Whereupon there is a retracement through the same software path as just described and then, upon repeated alarm occurrence, the software program terminates processing. As before, the retry process may be limited to a specified number of times.
Upon out-of-band callback verification being received, the biometric identification portion of the software program is initiated. In this present embodiment, while the biometric parameter that is monitored is speech, any of a number of parameters may be used. In this case, the control module <b>62</b> instructs the speech module <b>66</b> at SPEECH MODULE RETRIEVES PROMPT FOR USER block <b>198</b> to retrieve a prompt that for the purpose of later playing the prompt to the user and collecting the speech password. The speech module <b>66</b> queries the announcement database <b>130</b> and retrieves the prompt to be played to the user <b>24</b>. Besides using a prepared prompt, as above, a prompt synthesized by the text-to-speech system <b>90</b>, <b>92</b> and <b>94</b> is utilizable for this purpose.
The prompt for collecting the speech password is played to the user <b>24</b> at PROMPT USER AND COLLECT SPEECH PASSWORD block <b>200</b>. The user <b>24</b>, who has previously had his biometric sample, namely the speech pattern, registered with the speech database <b>128</b>, the voices the speech password at USER VOICES SPEECH PASSWORD block <b>202</b> and transmits the same over the telephone at the remote computer <b>22</b> to the security computer <b>40</b>. Then, at SPEECH MODULE RETRIEVES SPEECH PASSWORD ASSOCIATED WITH LOGIN ID block <b>204</b>, the software program for the speech module <b>66</b> is adapted to query the speech database <b>128</b> and to retrieve the speech password associated with the accessor's login identification. Through the application of biometric analysis, such as voice recognition technology, the speech or module <b>66</b> at SPEECH MODULE VERIFIES SPEECH PASSWORD block <b>206</b> verifies that the voiced speech password received from the user <b>24</b> has the same pattern as the speech password retrieved from database <b>128</b>.
Upon verification, the speech module <b>66</b> at DOES THE SPEECH PASSWORD MATCH? block <b>208</b> sends confirmation thereof back along the software pathway to inform the user of the event. Upon failure to verify, the speech module <b>66</b> at DOES THE SPEECH PASSWORD MATCH? block <b>208</b> notifies the control module <b>62</b> which initiates an alarm indicating that the login conditions were not met. The software program upon an alarm condition terminates processing. As in the previous password verification and alternatively, the program offers the user an opportunity to retry. Whereupon there is a retracement through the same software path as just described and then, upon repeated alarm occurrence, the software program terminates processing.
As before, the retry process may be limited to a specified number of times. Upon being notified of a match between the pattern of the voiced speech password and that of the one retrieved from the database <b>128</b>, the control module <b>62</b> at CONTROL MODULE INSTRUCTS SPEECH MODULE TO ANNOUNCE ACCESS IS GRANTED block <b>210</b> instructs the speech module <b>66</b> to provide an announcement to the user <b>24</b> indicating that access is granted. The speech module <b>66</b> queries the announcement database <b>130</b> and retrieves the announcement for the user <b>24</b>. Alternatively, the announcement can be synthesized by the text-to-speech system <b>90</b>, <b>92</b> and <b>94</b> and played to the user <b>24</b>. Whichever announcement is used, it is made to the user at ACCESS GRANTED ANNOUNCEMENT MADE TO USER block <b>212</b>.
Upon completion of the announcement at SPEECH MODULE NOTIFIES CONTROL MODULE OF ANNOUNCEMENT block <b>214</b>, the speech module <b>66</b> notifies the control module <b>62</b> that the announcement has been made to the user <b>24</b>. At this point at DISCONNECT TELEPHONE CONNECTION WITH USER block <b>215</b>, the control module <b>62</b> instructs the line module <b>64</b> to terminate the telephone connection and the telephone connection between the security computer <b>40</b> and user <b>24</b> is severed. At CONTROL MODULE SENDS AUTHENTICATION MESSAGE TO SERVER PROTOCOL MODULE block <b>216</b>, the message that the user <b>24</b> is authenticated is relayed by control module <b>62</b> to server protocol module <b>116</b> which is requested to communicate the same to the client protocol module <b>114</b>.
At SERVER PROTOCOL MODULE SENDS AUTHENTICATION MESSAGE TO CLIENT PROTOCOL MODULE block <b>217</b>, the message is relayed to the client protocol module <b>114</b> and thence via a proprietary protocol, at CLIENT PROTOCOL MODULE SENDS AUTHENTICATION MESSAGE TO HOST COMPUTER block <b>218</b>, to the host computer <b>34</b>. The host computer or web server <b>34</b> at HOST COMPUTER GRANTS ACCESS TO USER block <b>219</b> grants access to the authenticated used <b>24</b>.
In <figref idref="DRAWINGS">FIG. 10</figref> a schematic diagram of the second embodiment of the present invention is shown. For ease of comprehension, where similar components are used, reference designators “<b>200</b>” units higher are employed. In contrast to <figref idref="DRAWINGS">FIG. 1</figref> which describes the out-of-band security networks for computer networks of this invention as applied to the internet or wide area networks, this embodiment describes the application to local area networks. The second embodiment is referred to generally by the reference designator <b>220</b>. Here the accessor is the computer equipment <b>222</b>, including the central processing unit and the operating system thereof, and the person or user <b>224</b> whose voice is transmittable by the telephone <b>226</b> over telephone lines <b>228</b>.
While in this example the biometric parameter monitored is voice patterns as interpreted by voice recognition systems, any of a number of other parameters may be used to identify the person seeking access. The access network <b>230</b> is constructed in such a manner that, when user <b>224</b> requests access to a high security database <b>232</b> located at a host computer <b>234</b> through computer <b>222</b>, the request-for-access is diverted by a router <b>236</b> internal to the corporate network <b>238</b> to an out-of-band security network <b>240</b>. Here the emphasis is upon right-to-know classifications within an organization rather than on avoiding entry by hackers.
Thus, as the accessor is already within the system, the first level of verification of login identification and password at the host computer is the least significant and the authentication of the person seeking access is the most significant. Authentication occurs in the out-of-band security network <b>240</b>, which is analogous to the one described in detail above, except the subscriber database becomes layered by virtue of the classification. This is in contradistinction to present authentication processes as the out-of-band security network <b>240</b> is isolated from the corporate network <b>238</b> and does not depend thereon for validating data. The overview shows the bibmetric validation which, in this case, takes the form of a voice network <b>242</b>.
In <figref idref="DRAWINGS">FIG. 11</figref> a schematic diagram of the third embodiment of the present invention is shown. This embodiment describes the application of the security system to access over the internet. For ease of comprehension, where similar components are used, reference designators “<b>300</b>” units higher are employed. In contrast to <figref idref="DRAWINGS">FIG. 1</figref> which describes the out-of-band security networks for computer networks of this invention as applied to wide area networks, this embodiment describes the application to internet networks. The third embodiment is referred to generally by the reference designator <b>320</b>. The case of user accessing a web application, such as an online banking application, (located on a web server <b>334</b>) over the internet <b>330</b>. The user from a computer <b>322</b> accesses the web application over an access channel and enters their USER ID. The web server <b>334</b> sends the USER ID to the security system <b>340</b>, also referred to as the centralized out-of-band authentication system (COBAS). COBAS <b>340</b> proceeds with authenticating the user through the user's cellular telephone over an authentication channel. The security system <b>340</b> calls the access-seeking user at the cellular telephone <b>326</b>. The user answers the phone and is prompted to enter a password for password verification and to enter a biometric identifier, such as a fingerprint. The security system <b>340</b> authenticates the user and sends the result to the web server <b>334</b>. Upon a positive authentication and after disconnecting from the authentication channel, access is granted along the access channel to the USER'S PC device <b>322</b>.
The flow diagram for the COBAS device <b>340</b> software is analogous to that described in the first embodiment, supra, but for the speech module <b>66</b>. In lieu thereof, in <figref idref="DRAWINGS">FIG. 12</figref> the fingerprint module <b>366</b> architecture is detailed. The fingerprint verification hardware <b>384</b>, consists of digital signal processors that utilize algorithms for verification of an accessor's fingerprint. The fingerprint verification hardware <b>384</b> is controlled by the software program of the fingerprint hardware driver <b>386</b>. The software program of the fingerprint verification processing unit <b>388</b> provides an interface with control module <b>362</b> and is structured to respond to queries therefrom for verifying an accessor's password. Also, the fingerprint processing unit <b>388</b> enables the enrollment of users fingerprint and the interaction of the fingerprint database of the COBAS device <b>340</b>.
The text-to-speech (TTS) hardware <b>390</b> consists of digital signal processors that utilize TTS algorithms. The text-to-speech hardware <b>390</b> is controlled by the software program of the TTS hardware driver <b>392</b>. The software program of the TTS processing unit <b>394</b> provides an interface with the control module <b>362</b> and, as required by the control module <b>362</b>, converts text strings to synthesized speech. The announcement hardware <b>396</b> consists of digital signal processors that utilize speech algorithms to record and play announcements. The announcement hardware is controlled by the software program of the announcement hardware driver <b>398</b>. The software program of the announcement processing unit <b>400</b> also provides an interface with control module <b>362</b>; upon demands of the control module <b>362</b>, supplies stored announcements; and interacts with the announcements database of the related database (not shown).
In <figref idref="DRAWINGS">FIG. 13</figref> a schematic diagram of the fourth embodiment of the present invention is shown. This embodiment describes the application to PDAs (Personal Digital Assistant) . For ease of comprehension, where similar components are used, reference designators “<b>400</b>” units higher are employed. In contrast to <figref idref="DRAWINGS">FIG. 1</figref> which describes the out-of-band security networks for computer networks as applied to wide area networks, this embodiment describes the application to wireless networks including peripherals, such as PDAs and cellular telephones. The fourth embodiment is referred to generally by the reference designator <b>420</b>.
Although there are several PDAs currently marketing including the Blackberry and the Palm Computer, in this embodiment an HP iPAQ running on a Windows CE operating system is utilized. These PDAs have wireless capabilities and can also incorporate custom software applications. The HP iPAQ hereof incorporates a fingerprint reader. The security system <b>420</b> has two distinct and independent channels of operation, namely, the access channel and the authentication channel. The user from a computer <b>422</b> accesses the web application over an access channel and enters their USER ID. The web server <b>434</b> sends the USER ID to the security system <b>440</b>. COBAS <b>440</b> proceeds with authenticating the customer via the wireless network <b>442</b> over an authentication channel.
The security system <b>440</b> sends an authentication request message to a software program located on the PDA <b>422</b>. The software program prompts the user to enter their fingerprint. The COBAS security system <b>440</b> now authenticates the user's fingerprint against the template stored in its database and send the result to the web server <b>434</b>. Upon a positive authentication and after disconnecting from the authentication channel, access is granted along the access channel to the USER'S PDA device <b>422</b>.
Because many varying and different embodiments may be made within the scope of the inventive concept herein taught, and because many modifications may be made in the embodiments herein detailed in accordance with the descriptive requirement of the law, it is to be understood that the details herein are to be interpreted as illustrative and not in a limiting sense.
Contents6
20 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US10846427B2 | Cited by | United States of America | Search report |
| US9923883B2 | Cited by | United States of America | Applicant |
| US8462920B2 | Cited by | United States of America | Applicant |
| TWI704466B | Cited by | Taiwan Province of China | Examiner |
| US12363383B2 | Cited by | United States of America | Applicant |
| US10699028B1 | Cited by | United States of America | Applicant |
| US11088999B2 | Cited by | United States of America | Applicant |
| US10050945B2 | Cited by | United States of America | Applicant |
| US12452475B2 | Cited by | United States of America | Applicant |
| US12455978B1 | Cited by | United States of America | Applicant |
| US9300792B2 | Cited by | United States of America | Applicant |
| US10990979B1 | Cited by | United States of America | Applicant |
| US11831955B2 | Cited by | United States of America | Applicant |
| US2016182461A1 | Cited by | United States of America | Pre-grant |
| US10678913B2 | Cited by | United States of America | Applicant |
| US9584512B2 | Cited by | United States of America | Applicant |
| US11030562B1 | Cited by | United States of America | Applicant |
| US11580259B1 | Cited by | United States of America | Applicant |
| US2008103799A1 | Cited by | United States of America | Pre-grant |
| US11082743B2 | Cited by | United States of America | Applicant |
| US2013111566A1 | Cited by | United States of America | Pre-grant |
| US9275211B2 | Cited by | United States of America | Applicant |
| GB2501215B | Cited by | United Kingdom | Search report |
| US9762576B2 | Cited by | United States of America | Applicant |
| US2008120711A1 | Cited by | United States of America | Pre-grant |
| GB2501215A | Cited by | United Kingdom | Search report |
| US2011231911A1 | Cited by | United States of America | Pre-grant |
| US9875354B1 | Cited by | United States of America | Applicant |
| US10909617B2 | Cited by | United States of America | Applicant |
| US10896472B1 | Cited by | United States of America | Applicant |
| US8434133B2 | Cited by | United States of America | Search report |
| US10567385B2 | Cited by | United States of America | Applicant |
| US9832180B2 | Cited by | United States of America | Search report |
| US10178072B2 | Cited by | United States of America | Search report |
| US9167431B2 | Cited by | United States of America | Applicant |
| US9918345B2 | Cited by | United States of America | Applicant |
| US12335552B2 | Cited by | United States of America | Applicant |
| WO2012100079A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US2011035788A1 | Cited by | United States of America | Pre-grant |
| US9161222B2 | Cited by | United States of America | Applicant |
| US10715961B2 | Cited by | United States of America | Applicant |
| US2010293090A1 | Cited by | United States of America | Pre-grant |
| US9887991B2 | Cited by | United States of America | Applicant |
| US9935833B2 | Cited by | United States of America | Applicant |
| WO2012100079A2 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US9710868B2 | Cited by | United States of America | Applicant |
| US10687371B2 | Cited by | United States of America | Applicant |
| US10965727B2 | Cited by | United States of America | Applicant |
| US8640254B2 | Cited by | United States of America | Search report |
| US10560772B2 | Cited by | United States of America | Applicant |
| US11436606B1 | Cited by | United States of America | Applicant |
| US8516560B2 | Cited by | United States of America | Applicant |
| US2017078284A1 | Cited by | United States of America | Pre-grant |
| US2020159956A1 | Cited by | United States of America | Search report |
| US11381549B2 | Cited by | United States of America | Applicant |
| US11157650B1 | Cited by | United States of America | Applicant |
| US8745219B2 | Cited by | United States of America | Search report |
| US10164858B2 | Cited by | United States of America | Applicant |
| US10108963B2 | Cited by | United States of America | Search report |
| US2010180326A1 | Cited by | United States of America | Pre-grant |
| US11356819B2 | Cited by | United States of America | Applicant |
| US9986578B2 | Cited by | United States of America | Applicant |
| US8365258B2 | Cited by | United States of America | Applicant |
| US9674224B2 | Cited by | United States of America | Applicant |
| US11412320B2 | Cited by | United States of America | Applicant |
| US9930040B2 | Cited by | United States of America | Applicant |
| US2008163381A1 | Cited by | United States of America | Pre-grant |
| US12045755B1 | Cited by | United States of America | Applicant |
| US10362018B2 | Cited by | United States of America | Applicant |
| US10958629B2 | Cited by | United States of America | Applicant |
| US12099940B1 | Cited by | United States of America | Applicant |
| US9094387B2 | Cited by | United States of America | Search report |
| US11669595B2 | Cited by | United States of America | Applicant |
| US11540148B2 | Cited by | United States of America | Applicant |
| US10122715B2 | Cited by | United States of America | Search report |
| US11076203B2 | Cited by | United States of America | Applicant |
| US10848806B2 | Cited by | United States of America | Applicant |
| US9973798B2 | Cited by | United States of America | Applicant |
| US10278008B2 | Cited by | United States of America | Applicant |
| US2015288674A1 | Cited by | United States of America | Pre-grant |
| US2008010687A1 | Cited by | United States of America | Pre-grant |
| US12261957B2 | Cited by | United States of America | Search report |
| US10474838B1 | Cited by | United States of America | Search report |
| US10645547B2 | Cited by | United States of America | Applicant |
| US9742768B2 | Cited by | United States of America | Applicant |
| US9380045B2 | Cited by | United States of America | Search report |
| US9712528B2 | Cited by | United States of America | Search report |
| US10592982B2 | Cited by | United States of America | Applicant |
| US8687038B2 | Cited by | United States of America | Applicant |
| US9813905B2 | Cited by | United States of America | Applicant |
| US8935769B2 | Cited by | United States of America | Applicant |
| US2024080201A1 | Cited by | United States of America | Search report |
| US11146470B2 | Cited by | United States of America | Applicant |
| US11197050B2 | Cited by | United States of America | Applicant |
| US2010241850A1 | Cited by | United States of America | Pre-grant |
| US10219154B1 | Cited by | United States of America | Applicant |
| US10593004B2 | Cited by | United States of America | Applicant |
| US10492034B2 | Cited by | United States of America | Applicant |
| US9781107B2 | Cited by | United States of America | Applicant |
| US10638361B2 | Cited by | United States of America | Applicant |
13 members in 2 offices
Priority claims6
| Document | Office | Kind | Date |
|---|---|---|---|
| 65529700 | United States of America | A | |
| 65529700 | United States of America | A | |
| 97055904 | United States of America | A | |
| 09655297 | – | – | – |
| US20000655297 | – | – | – |
| US20040970559 | – | – | – |
Members13
| Document | Office | Kind | |
|---|---|---|---|
| US2006041755A1 | United States of America | A1 | |
| WO2006047164A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2006047164A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2006047164A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO2006047164A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US7870599B2This record | United States of America | B2 | |
| US2013096916A1 | United States of America | A1 | |
| US8484698B2 | United States of America | B2 | |
| US2013227665A1 | United States of America | A1 | |
| US2014109203A1 | United States of America | A1 | |
| US8713701B2 | United States of America | B2 | |
| US2017006040A1 | United States of America | A1 | |
| US2017366556A1 | United States of America | A1 |
73 transactions on the USPTO file
Allowed after 2 non-final rejections, 2 final rejections, 1 RCE and 2 appeals.
- Non-final rejections
- 2
- Final rejections
- 2
- RCEs
- 1
- Appeals
- 2
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Expire PatentEXP. | EXP. | |
| Maintenance Fee Reminder MailedREM. | REM. | |
| Payment of Maintenance Fee, 8th Year, Large EntityM1552 | M1552 | |
| Entity status set to undiscounted (initial default setting or status change)BIG. | BIG. | |
| Post Issue Communication - Certificate of CorrectionN423 | N423 | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Workflow - Request for RCE - FinishFRCE | FRCE | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Appeal Brief Review CompleteAPBR | APBR | |
| Appeal Brief FiledAP.B | AP.B | |
| Mail Appeals conf. Proceed to BPAIMAPCP | MAPCP | |
| Pre-Appeals Conference Decision - Proceed to BPAIAPCP | APCP | |
| Request for Pre-Appeal Conference FiledAP.C | AP.C | |
| Notice of Appeal FiledN/AP | N/AP | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Mail Examiner Interview Summary (PTOL - 413)MEXIN | MEXIN | |
| Examiner Interview Summary Record (PTOL - 413)EXIN | EXIN | |
| Affidavit(s) (Rule 131 or 132) or Exhibit(s) ReceivedAF/D | AF/D | |
| Request for RefundIRFND | IRFND | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Workflow - Request for RCE - FinishFRCE | FRCE | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Mail Advisory Action (PTOL - 303)MCTAV | MCTAV | |
| Advisory Action (PTOL-303)CTAV | CTAV | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Affidavit(s) (Rule 131 or 132) or Exhibit(s) ReceivedAF/D | AF/D | |
| Amendment/Argument after Notice of AppealAP/A | AP/A | |
| Notice of Appeal FiledN/AP | N/AP | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Correspondence Address ChangeC.AD | C.AD | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Affidavit(s) (Rule 131 or 132) or Exhibit(s) ReceivedAF/D | AF/D | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Response after Non-Final ActionA... | A... | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| IFW TSS Processing by Tech Center CompleteTSSCOMP | TSSCOMP | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Rescind Nonpublication Request for Pre Grant PublicationRESC | RESC | |
| Application Return from OIPEWROIPE | WROIPE | |
| Application Return TO OIPEROIPE | ROIPE | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Application Is Now CompleteCOMP | COMP | |
| Cleared by OIPE CSRL194 | L194 | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| PGPubs nonPub RequestNPRQ | NPRQ | |
| Initial Exam Team nnIEXX | IEXX |
16 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Lapsed due to failure to pay maintenance feeLapsedFP | FP | |
| Lapse for failure to pay maintenance feesLapsedPATENT EXPIRED FOR FAILURE TO PAY MAINTENANCE FEES (ORIGINAL EVENT CODE: EXP.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYLAPS | LAPS | |
| Information on status: patent discontinuationPATENT EXPIRED DUE TO NONPAYMENT OF MAINTENANCE FEES UNDER 37 CFR 1.362STCH | STCH | |
| Fee payment procedureMAINTENANCE FEE REMINDER MAILED (ORIGINAL EVENT CODE: REM.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| Fee payment procedureENTITY STATUS SET TO UNDISCOUNTED (ORIGINAL EVENT CODE: BIG.)FEPP | FEPP | |
| Maintenance fee paymentMAFP | MAFP | |
| AssignmentAS | AS | |
| Certificate of correctionCC | CC | |
| AssignmentAS | AS | |
| Fee paymentFPAY | FPAY | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Reexamination certificate first reexaminationTHE PATENTABILITY OF CLAIMS 1-34 IS CONFIRMED. NEW CLAIMS 35-42 ARE ADDED AND DETERMINED TO BE PATENTABLE.B1 | B1 | |
| Request for reexamination filedRR | RR | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS |
Numbers
- Publication
- 07870599
- Publication, DOCDB
- 7870599
- Publication, EPODOC
- US7870599
- Application
- 10970559
- Application, DOCDB
- 97055904
- Application, EPODOC
- US20040970559
Titles
- English
- Multichannel device utilizing a centralized out-of-band authentication system (COBAS)
Patent term adjustment
- A delay
- +630 daysthe office missed an examination deadline
- B delay
- +416 dayspendency past three years
- Applicant delay
- −289 days
- Net adjustment
- 757 days
Classification
- CPC, 9
- G06F21/32
- H04L63/102
- G06F21/42
- H04L63/083
- H04L63/18
- H04L9/3215
- H04L9/3231
- H04L63/0861
- H04L63/08
- IPC, 3
- G06F7 04
- G06F21 00
- H04L29 06
- USPC, 10
- 726002000
- 340005800
- 340005810
- 340005820
- 340005830
- 340005840
- 713168000
- 713169000
- 713186000
- 726004000